Troubleshooting PROFIBUS Fieldbus Failure on Siemens S7-300 PLCs

David Krause13 min read
S7-300SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

PROFIBUS DP is the dominant fieldbus on legacy SIMATIC S7-300 automation cells. Most field cells in service today run either at 187.5 kbps (cost-optimised networks with long cable runs and many ET 200 stations) or 1.5 Mbps (typical default for drives, valves, and high-density I/O). Engineers report an unusual failure pattern: a network that runs flawlessly for months at 187.5 kbps suddenly accumulates BF (Bus Fault) events, SF (System Fault) flags, and slave station dropouts the moment the baud rate is increased to 1.5 Mbps. The bus is not broken; the noise budget is. This reference documents the root cause, the diagnostic workflow, and the field-proven fixes for that specific failure mode on S7-300 CPUs and ET 200 stations.

Safety: Disconnect the 24 V supply to the PROFIBUS segments and the 400/480 V drive DC bus before any connector rework. Lock out and tag out the panel per local electrical safety rules. Re-energise only after all shield clamps, bus terminators, and connector screws have been re-torqued to spec.

Symptoms and Fault Indicators on the S7-300

Recognise the failure before changing anything. On the S7-300 the PROFIBUS DP interface is integrated into the CPU (CPU 313C, 314, 315-2 DP, 317-2, 319-3) or, in older builds, in the CP 342-5 communications processor. The visible indicators are:

LED / Signal Location Meaning
SF (red, steady) CPU front System fault; diagnostic buffer contains a PROFIBUS entry.
BF (red, steady) CPU / CP 342-5 front Bus fault; no token / no frame from at least one slave.
BF (red, flashing) CPU / CP 342-5 front Bus fault; partial slave loss or intermittent frames.
ON (green, off) ET 200S / ET 200M IM 153 Slave lost token or saw no valid frame for the watchdog time.
SF (red, on slave) ET 200 station Slave diagnostic pending; check station diagnostics.
OB86, OB122, OB82 PLC program Loss of slave, I/O access error, diagnostic interrupt (call the OB to capture the start info).

Read the diagnostic buffer in STEP 7 (TIA Portal) or STEP 7 V5.x via Online > Diagnostic > Buffer. Typical entries that confirm the fieldbus-versus-speed failure mode include "DP slave failure", "Bus fault at DP master", and "Frame error on PROFIBUS DP". Each BF event is logged with a UTC timestamp and the station number; if the events correlate with the moment the operator commanded the drive to ramp, the root cause is almost always EMC, not the bus protocol.

Root Cause: Why 187.5 kbps Works and 1.5 Mbps Does Not

PROFIBUS DP uses RS-485 differential signalling on a shielded twisted pair. The receiver decodes bits by sampling the voltage difference between the two conductors at a fixed time window. The time window shrinks linearly with the bit period. At 187.5 kbps each bit is 5.33 µs wide; at 1.5 Mbps each bit is 0.667 µs wide. That 8:1 reduction in bit period means the receiver has 8 times less energy integration window to reject common-mode noise, intersymbol interference, and cable reflections.

Three physical effects converge to create the failure at 1.5 Mbps:

  1. Cable attenuation is bandwidth-limited. A real PROFIBUS cable (Siemens 6XV1830-0EH10, violet jacket) has a specified attenuation of about 2.5 dB/100 m at 16 MHz. At 1.5 Mbps the third harmonic of the bit stream is already inside the region where the cable starts to roll off. If the cable is the wrong type, is kinked, or has a poorly crimped connector, the eye opening collapses first at the highest frequency components.
  2. Stub length and connector capacitance. The 9-pin D-sub PROFIBUS connector adds about 15–25 pF of parasitic capacitance. Each ET 200 station on the segment adds its connector capacitance. At 187.5 kbps the resulting RC low-pass corner is well above the bit rate. At 1.5 Mbps the same cable plant is operating close to its 3 dB point, so every additional station pushes the bit error rate up.
  3. Common-mode noise from the VFD. Modern IGBT inverters (SINAMICS G120, G130, S120, Micromaster 4) switch the DC bus at 4–16 kHz with edge rates in the 50–200 ns range. The dv/dt couples capacitively to the PROFIBUS cable if the shield is not bonded to the cabinet ground at both ends with low-impedance clamps. At 187.5 kbps the differential receiver integrates the noise out. At 1.5 Mbps the noise spike lands inside a single bit and corrupts it.

The combination of these three is what field engineers describe as: "The network is fine at 187.5 kbps, but faults at 1.5 Mbps." The cure is to attack all three: rebuild the cable plant, bond the shields properly, and isolate the drive from the bus.

Prerequisites for the Fix

  • STEP 7 V5.5 SP4 or TIA Portal V16+ with the SIMATIC S7-300 HSP.
  • Siemens PROFIBUS cable 6XV1830-0EH10 (or 6XV1830-3EH10 for trailing / festoon). See Siemens catalog IK PI.
  • PROFIBUS connectors with 90° or 35° cable outlet and integrated switchable terminator: 6ES7972-0BA12-0XA0, 6ES7972-0BB12-0XA0, 6ES7972-0BA52-0XA0 (axially mounted). Do not use hard-wired pigtails.
  • EMC shield clamps sized to the cable (e.g. Phoenix Contact SK 14, Weidmüller KLBÜ 4–13.5).
  • Reference equipotential bonding conductor, 16 mm² Cu minimum for industrial cabinets per IEC 60364-5-54.
  • Diagnostic tool: Siemens BT 200 PROFIBUS tester, or a softing PROFINET/PROFIBUS diagnostic tool, or a Tektronix TDS 3054 with a differential probe to look at the eye.

Step-by-Step Diagnostic and Repair Procedure

Step 1 – Confirm the Symptom in the Diagnostic Buffer

Open STEP 7, go online to the CPU, and read the diagnostic buffer. Look for the pattern: bus faults that appear only after 1.5 Mbps is set and that increase in frequency when the drive is given a run command. If the faults persist at 187.5 kbps with the drive de-energised, the bus hardware is broken. If they vanish at 187.5 kbps and reappear at 1.5 Mbps, the problem is the noise budget, not the bus controller.

Step 2 – Verify the Baud Rate and Bus Profile

In HW Config or TIA Portal, open the DP master system properties and confirm the transmission rate is actually 1.5 Mbps, not auto-detected to a lower rate. Some third-party slave GSD files will negotiate the bus down. Set the baud rate to a fixed value and download the configuration. Recompile the hardware configuration and re-download it. A common field mistake is to change the master baud rate and forget to re-download the slave configurations.

Step 3 – Inspect the PROFIBUS Connectors

Remake every connector on the segment. Strip 25 mm of the outer jacket, fold the shield back over the jacket, and clamp it inside the connector's 360° shield clamp. Screw the two data wires (green and red) into the terminal block; the screw torque should be 0.4 N·m. Tighten the strain relief. Bad crimps or loose terminal screws are the number one cause of intermittent bus faults that scale with baud rate. Slide the terminator switch to ON on the two end stations only; every other station must be OFF. Confirm by walking the segment: the first and last physical station should be the only ones with the switch down.

Step 4 – Verify the Cable Type and Length

Use only the violet Siemens 6XV1830-0EH10 cable (or a third-party cable that meets the PROFIBUS cable spec: 150 Ω ± 15 Ω characteristic impedance, 3.0 dB/100 m at 1 MHz, 9.6 dB/100 m at 20 MHz). Maximum segment length at 1.5 Mbps is 200 m without repeaters; at 187.5 kbps it is 1 000 m. If the segment is longer than 200 m at 1.5 Mbps, install a PROFIBUS RS-485 repeater (6GK1500-0AA00) mid-segment. Do not coil excess cable; the unused portion is a 150 Ω stub that attenuates the high-frequency components.

Step 5 – Bond the Shield at Both Ends, Low Impedance

Each segment of PROFIBUS cable should have its shield clamped to a grounded backplane at both the cabinet entry and at every intermediate cabinet. The shield clamp must be 360° (do not use pigtails). The bonding conductor from the shield clamp to the cabinet backplane should be 16 mm² Cu braided or stranded, as short as practical, and should not pass through any current-carrying conductor. If the drive cabinet and the PLC cabinet have different ground potentials, install a heavy equipotential bonding conductor (≥ 10 mm²) between the two cabinets. A difference of even 5 V in ground potential can shift the PROFIBUS common-mode voltage outside the receiver's range.

Step 6 – Separate the Drive Power Cables from the PROFIBUS Cable

Maintain at least 200 mm of physical separation between the PROFIBUS cable and any VFD input or output power cable. Cross them at 90° if they must intersect. The motor output cable of a VFD is the worst offender: it carries the chopped PWM waveform and radiates strongly. Use shielded motor cable with the shield bonded at the drive end and the motor end; route the motor cable in its own conduit at least 300 mm away from the PROFIBUS cable. Install a sinus filter or output reactor on the VFD output if the motor cable is longer than 50 m.

Step 7 – Add a Repeater to Insert Galvanic Isolation

If the faults persist after the cable and shield work, insert a PROFIBUS repeater with electrical isolation (6GK1500-0AA10) between the drive cabinet and the PLC cabinet. The repeater regenerates the signal levels and provides 1.5 kV DC galvanic isolation. This single device has, in field experience, fixed the majority of 1.5 Mbps bus faults caused by VFD common-mode noise.

Step 8 – Check the Termination Resistor Value

The bus terminator on the 9-pin D-sub connector is a 220 Ω resistor from each data line to +5 V and to GND, in parallel with a 390 Ω resistor between the two data lines, giving the classic 150 Ω termination between the two lines. This is built into the Siemens 6ES7972-0BA12-0XA0 connector. Confirm that the connector is the active terminator and not a passive one. A failed terminator resistor (often caused by repeated over-current on a mis-wired bus) will give perfect operation at 187.5 kbps and intermittent faults at 1.5 Mbps.

Diagnostic Buffer Codes and What They Mean

The S7-300 diagnostic buffer entries that are most useful for this failure mode are:

Event ID (hex) Plain Text Likely Cause
0x3942 DP slave failure (station number) Slave lost token; cable or EMC issue.
0x3945 DP slave: return of station Slave recovered; check for intermittent events.
0x3A82 Diagnostic interrupt from slave Slave reports internal diagnostic; inspect slave HW.
0x3B82 DP slave has incorrect configuration GSD version mismatch; re-download HW Config.
0x3C82 Time-out on DP Watchdog timeout; cable loss or noise.
0x3D82 Bus fault, DP master Master detected repeated frame errors.
0x3E82 Bus short-circuit on DP Physical short on bus wires; inspect connectors.
0x4F22 Error in lower-level firmware CP 342-5 firmware; upgrade if persistent.
Event ID values are platform-specific; cross-check the actual ID against the firmware of your CPU or CP. The plain-text description is the stable identifier across firmware versions.

Specifications Reference

Parameter 187.5 kbps 1.5 Mbps
Max segment length (no repeater) 1 000 m 200 m
Max segment length (3 repeaters) 4 000 m 800 m
Max number of stations per segment 32 32
Bit period 5.33 µs 0.667 µs
Recommended cable 6XV1830-0EH10 6XV1830-0EH10
Recommended connector 6ES7972-0BA12-0XA0 6ES7972-0BA12-0XA0
Min shield bonding area 360° 360°
Min equipotential bond 16 mm² Cu 16 mm² Cu
Min drive cable separation 200 mm 200 mm

Verification Procedure

  1. Power-cycle the S7-300 CPU and the ET 200 stations. Confirm the BF and SF LEDs go off within 5 seconds of power-up.
  2. Force a heavy drive load (full speed, full torque, repeated ramps) and watch the BF LED for at least 30 minutes. The CPU diagnostic buffer should remain free of new bus fault events.
  3. Read the slave diagnostic frames using STEP 7 Online > PROFIBUS Diagnostics. All stations should show "OK" status. Slaves that were dropping out should now show continuous operation.
  4. Capture the PROFIBUS eye pattern with an oscilloscope at the last station on the segment. The differential eye should have at least 1.0 V of vertical opening and the bit period should be clean of ringing or noise transients exceeding ±0.5 V.
  5. Run a loopback stress test: read 32 bytes from the last slave 1 000 times in 1 second and count parity / framing errors. Acceptable rate is zero errors over 1 000 000 reads.

Field-Proven Checklist

  • Use only Siemens 6ES7972-0BA12-0XA0 (or -0BA52) PROFIBUS connectors with switchable termination.
  • Activate the terminator on the first and last physical station only. Switch it OFF on every intermediate station.
  • Clamp the shield 360° at every cabinet entry with a low-impedance EMC clamp.
  • Maintain 200 mm separation between the PROFIBUS cable and any VFD power cable. Cross at 90° if intersection is unavoidable.
  • Bind the drive cabinet and the PLC cabinet to a common equipotential bonding conductor of at least 16 mm².
  • Limit each segment to 200 m at 1.5 Mbps; install a 6GK1500-0AA10 repeater for galvanic isolation if the drive cabinet is a major noise source.
  • Use shielded VFD output cable and bond both ends. Add a sinus filter for motor cables longer than 50 m.
  • Re-torque the data-wire terminal screws to 0.4 N·m on every connector after any rework.
  • Document the final baud rate, segment topology, and termination status in the cabinet drawing.

Frequently Asked Questions

Why does my PROFIBUS network work at 187.5 kbps but fail at 1.5 Mbps on the S7-300?

At 1.5 Mbps the bit period is 0.667 µs, eight times shorter than at 187.5 kbps. Cable attenuation, connector capacitance, and common-mode VFD noise that are tolerable at the lower baud rate corrupt the bit at the higher one. The cure is a rebuilt cable plant, 360° shield bonding at both ends, 200 mm minimum separation from drive cables, and often a 6GK1500-0AA10 isolated repeater between the drive cabinet and the PLC.

Which Siemens PROFIBUS connectors should I use for S7-300 stations?

Use the 6ES7972-0BA12-0XA0 (90° cable outlet) or 6ES7972-0BB12-0XA0 (35° outlet) for stations inside a cabinet, and 6ES7972-0BA52-0XA0 (axial outlet) for inline or IP65 stations. All three have a switchable integrated terminator and a 360° shield clamp. Avoid hard-wired pigtail wiring; pigtails raise the bus error rate at any baud rate above 500 kbps.

How do I find the exact station that is dropping out of the bus?

Open STEP 7 online, navigate to PLC > PROFIBUS Diagnostics, and look at the station list. The failed station will be shown in red. Cross-reference the station number with the diagnostic buffer event ID, which logs the specific station number in the event text. Alternatively, walk the segment with a BT 200 or a softing PROFIBUS tester to read the live signal levels per station.

Can a SINAMICS G120 drive cause an S7-300 PROFIBUS fault at 1.5 Mbps?

Yes. The IGBT output stage of a G120 (and any modern inverter) has edge rates of 50–200 ns and can couple noise into the PROFIBUS cable through capacitive paths if the shield is not bonded 360° at both ends and the motor cable is not shielded. Add a sinus filter on the drive output for motor cables longer than 50 m, and place a PROFIBUS repeater with electrical isolation (6GK1500-0AA10) between the drive cabinet and the PLC cabinet to break the common-mode path.

What is the maximum PROFIBUS cable length at 1.5 Mbps on the S7-300?

200 m per segment without repeaters, and 800 m total when three repeaters (6GK1500-0AA00 or -0AA10) are used. Lengths beyond 200 m at 1.5 Mbps will give eye closure before the receiver decoding threshold and the diagnostic buffer will fill with frame errors. Use the Siemens 6XV1830-0EH10 violet cable exclusively; substitutes must meet the 150 Ω ± 15 Ω impedance and the specified attenuation.

Back to blog